CVE-2023-33189

CRITICAL

Pomerium <0.17.3 - Auth Bypass

Title source: llm
STIX 2.1

Description

Pomerium is an identity and context-aware access proxy. With specially crafted requests, incorrect authorization decisions may be made by Pomerium. This issue has been patched in versions 0.17.4, 0.18.1, 0.19.2, 0.20.1, 0.21.4 and 0.22.2.

Scores

CVSS v3 10.0
EPSS 0.0026
EPSS Percentile 49.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-285
Status published
Products (4)
pomerium/pomerium 0.18.0
pomerium/pomerium 0.20.0
pomerium/pomerium < 0.17.4
pomerium/pomerium 0.22.0 - 0.22.2Go
Published May 30, 2023
Tracked Since Feb 18, 2026